Security experts over at McAfee believe they’ve unearthed a new crafty piece of Android malware dubbed NoVoice lurking on Google Play. This troublesome malware is disguised within over 50 distinct Android applications and has been downloaded at least 2.3 million times. Yes, 2.3 million!
How the malware camouflages itself
The applications containing NoVoice masquerade as cleaning tools, photo albums, or games, according to the US IT security news outlet BleepingComputer. Upon installation, these applications don’t request any absurd permissions, making them appear innocuous, especially since they even perform as advertised.
Complete control over infected Android devices
After launching the suspicious app, the malware attempts to gain root access on your Android device by exploiting outdated Android security vulnerabilities that were patched long ago between 2016 and 2021. The malware then communicates with the command-and-control server (C2) and reports details about your device – including hardware, kernel, Android version, installed applications, and root status – to determine its next actions.
It then pulls in additional components to mount a comprehensive assault on your unfortunate Android device. The attacker exploits 22 different vulnerabilities to bypass the Android device’s security and ultimately obtains root privileges, resembling complete authority over your phone.
Once in control, it replaces crucial system libraries like libandroid_runtime.so and libmedia_jni.so with its modified versions that misdirect everything to its malicious code, as noted by BleepingComputer.
It persists even after a reset
This malware is quite resilient. Even conducting a factory reset may not eliminate it, as McAfee states: “At times, the infection can linger after a basic factory reset because the sneaky components modify system software that isn’t altered during the reset.” It embeds its harmful code into every application you access on your device, with WhatsApp being its preferred target.
Security professionals are unclear about who developed this malware. However, they have observed that it shares similarities with the Android Trojan Triada, which has caused issues in the past.
Optimal protection: install all security updates
Google has removed the compromised applications from Google Play, but if you have already interacted with them, your device remains at risk. Nice, right?
However, here’s a clever suggestion: since NoVoice targets security vulnerabilities resolved by May 2021, upgrading to a device with the latest updates should protect you. Ensure you update your Android device to the most current version or consider purchasing a new one if yours is outdated.
Replace any phone that hasn’t received security updates in a long time, and we’ve got some excellent recommendations for the best devices and budget options we’ve evaluated.
McAfee adds: “To completely eradicate the infection, you might need to reinstall the device’s firmware, which isn’t an easy task for most users.”
These Android devices are secure
Android devices running a recent version with all necessary security updates should be secure. McAfee mentions: “On older or unpatched Android devices, the malware can establish a stronghold quite comfortably, possibly surviving a factory reset. While newer Android devices won’t fall victim to the same root exploit from this incident, they could still encounter other types of trouble through these applications.”
For more technical insights, refer to McAfee’s comprehensive analysis.
Ways to protect yourself
Only obtain applications from Google Play, and avoid other app marketplaces (not that it helped much this time). Ensure Google Play Protect is enabled and utilize a virus scanner.
Before downloading any application, scrutinize its permissions, evaluate the download statistics, and read the reviews on Google Play. Always apply those Android security updates as soon as they become available.
More on Android:
Don’t Get Your Wires Crossed
It seems our Android companions have some unwelcome visitors. Keep those devices fully updated, or you might find yourself grappling with more malware than from a sketchy website! Stay sharp, everyone.